Cheat Engine Forum Index Cheat Engine
The Official Site of Cheat Engine
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 


C++ Bypassing
Goto page Previous  1, 2
 
Post new topic   Reply to topic    Cheat Engine Forum Index -> General programming
View previous topic :: View next topic  
Author Message
rapion124
Grandmaster Cheater Supreme
Reputation: 0

Joined: 25 Mar 2007
Posts: 1095

PostPosted: Fri Aug 15, 2008 7:21 pm    Post subject: Reply with quote

sponge wrote:
Xoujiro wrote:
Quote:
7c81e079


ok, thanks, can i use olly to check which bytes are overwritten?
XTrap will detect a barebones Olly.


There's something called Phantom for Olly. It hides Olly o_O. Although XTrap's hooks prevent OllyDBG from functioning, it makes things a lot easier because XTrap won't reboot your computer.

I have some experience with XTrap. I also play Wolfteam. What you need to do is get the Phantom plugin, open Olly, and put a breakpoint on CreateProcessA. Run Wolfteam and you should get a hit. Now, just go to [esp] and you got the address of the game loading XTrap. Phantom is required because Wolfteam.bin is packed with ASProtect, so it will give you a debugger detected error if Olly is detected.
Back to top
View user's profile Send private message
Xoujiro
Advanced Cheater
Reputation: 0

Joined: 20 Mar 2006
Posts: 86

PostPosted: Fri Aug 15, 2008 8:13 pm    Post subject: Reply with quote

Ok, so ive got the addy and all, but the same address is obtained whether wolfteam is running or not, does this mean it isnt hooked?

and rapion, i ran olly, ctrl+g and typed in CreateProcessA, it brought me to kernel32.dll, now i right click -> breakpoint -> toggle , and then run wolfteam, now what do i do?
Back to top
View user's profile Send private message
dnsi0
I post too much
Reputation: 0

Joined: 04 Jan 2007
Posts: 2674

PostPosted: Fri Aug 15, 2008 8:33 pm    Post subject: Reply with quote

k. Look for createprocessA in intermodular calls. Now you should find 3.
(well... thats for gameguard) then you look for one that has PUSH 01 above it by a few bytes. Change the PUSH 1 to PUSH 0.
(well... thats for gameguard so I don't know if its gonna work for xtrap)
Back to top
View user's profile Send private message
Xoujiro
Advanced Cheater
Reputation: 0

Joined: 20 Mar 2006
Posts: 86

PostPosted: Fri Aug 15, 2008 8:52 pm    Post subject: Reply with quote

dnsi0 wrote:
k. Look for createprocessA in intermodular calls. Now you should find 3.
(well... thats for gameguard) then you look for one that has PUSH 01 above it by a few bytes. Change the PUSH 1 to PUSH 0.
(well... thats for gameguard so I don't know if its gonna work for xtrap)


There are so many intermodular calls... do i have to look 1 by 1 or can i search for it
Back to top
View user's profile Send private message
rapion124
Grandmaster Cheater Supreme
Reputation: 0

Joined: 25 Mar 2007
Posts: 1095

PostPosted: Fri Aug 15, 2008 8:55 pm    Post subject: Reply with quote

Wow!!!!! Do you need to be spoonfed? Breakpoint on CreateProcessA. Run Wolfteam. Look in the lpFileName or lpCommandLine parameters. Look for "XTrap.xt" in those parameters. Then go to [esp] to get the address the game calls to load XTrap.

Note: you will get multiple hits, it's expected.
Back to top
View user's profile Send private message
Xoujiro
Advanced Cheater
Reputation: 0

Joined: 20 Mar 2006
Posts: 86

PostPosted: Fri Aug 15, 2008 10:01 pm    Post subject: Reply with quote

nvm i give up
Back to top
View user's profile Send private message
sponge
I'm a spammer
Reputation: 1

Joined: 07 Nov 2006
Posts: 6009

PostPosted: Fri Aug 15, 2008 10:57 pm    Post subject: Reply with quote

rapion124 wrote:
sponge wrote:
Xoujiro wrote:
Quote:
7c81e079


ok, thanks, can i use olly to check which bytes are overwritten?
XTrap will detect a barebones Olly.


There's something called Phantom for Olly. It hides Olly o_O. Although XTrap's hooks prevent OllyDBG from functioning, it makes things a lot easier because XTrap won't reboot your computer.

I have some experience with XTrap. I also play Wolfteam. What you need to do is get the Phantom plugin, open Olly, and put a breakpoint on CreateProcessA. Run Wolfteam and you should get a hit. Now, just go to [esp] and you got the address of the game loading XTrap. Phantom is required because Wolfteam.bin is packed with ASProtect, so it will give you a debugger detected error if Olly is detected.
Yes, I already knew that. Anyways WolfTeam is packed with Themida not ASProtect.
_________________
Back to top
View user's profile Send private message
Slugsnack
Grandmaster Cheater Supreme
Reputation: 71

Joined: 24 Jan 2007
Posts: 1857

PostPosted: Sat Aug 16, 2008 4:18 am    Post subject: Reply with quote

Xoujiro wrote:
nvm i give up

Mate.. Look at CreateProcess (http://msdn.microsoft.com/en-us/library/ms682425.aspx). Now look at the parameters:

Quote:
BOOL WINAPI CreateProcess(
__in_opt LPCTSTR lpApplicationName,
__inout_opt LPTSTR lpCommandLine,
__in_opt LPSECURITY_ATTRIBUTES lpProcessAttributes,
__in_opt LPSECURITY_ATTRIBUTES lpThreadAttributes,
__in BOOL bInheritHandles,
__in DWORD dwCreationFlags,
__in_opt LPVOID lpEnvironment,
__in_opt LPCTSTR lpCurrentDirectory,
__in LPSTARTUPINFO lpStartupInfo,
__out LPPROCESS_INFORMATION lpProcessInformation


Now you have it essentially 'hooked' and you can keep going till the lpApplicationName matches XTrap. Then you can look on the stack for the return address (ie. where the call will ret to after it's done) and looking at the instruction before that will tell you the VA to the call to XTrap.
Back to top
View user's profile Send private message
atom0s
Moderator
Reputation: 205

Joined: 25 Jan 2006
Posts: 8588
Location: 127.0.0.1

PostPosted: Sat Aug 16, 2008 5:49 am    Post subject: Reply with quote

Does WolfTeam do packet checks with XTrap? (I assume they do cause the game is made by Softnyx..)

If not you can unhook Xtrap from the game completely fairly easy.

_________________
- Retired.
Back to top
View user's profile Send private message Visit poster's website
dnsi0
I post too much
Reputation: 0

Joined: 04 Jan 2007
Posts: 2674

PostPosted: Sat Aug 16, 2008 8:27 am    Post subject: Reply with quote

K. Look for intermodular calls but use sort->by name

then its in alphabetical order.
Back to top
View user's profile Send private message
Wintermoot
Expert Cheater
Reputation: 0

Joined: 08 Nov 2007
Posts: 198

PostPosted: Sat Aug 16, 2008 9:16 am    Post subject: Reply with quote

Lok for all intermodular calls then start typing and look at the window's titlebar...
Back to top
View user's profile Send private message
Slugsnack
Grandmaster Cheater Supreme
Reputation: 71

Joined: 24 Jan 2007
Posts: 1857

PostPosted: Sat Aug 16, 2008 9:21 am    Post subject: Reply with quote

As I said before, if the game is packed, it is unlikely the method you two are describing will work.

But by placing a breakpoint on the actual function itself, it will catch it unless the breakpointed instruction is not executed or the breakpoint removed.
Back to top
View user's profile Send private message
Xoujiro
Advanced Cheater
Reputation: 0

Joined: 20 Mar 2006
Posts: 86

PostPosted: Sat Aug 16, 2008 9:52 am    Post subject: Reply with quote

i dont know anything about olly... and there are checksums to check for xtrap too

Last edited by Xoujiro on Sat Aug 16, 2008 10:18 am; edited 1 time in total
Back to top
View user's profile Send private message
rapion124
Grandmaster Cheater Supreme
Reputation: 0

Joined: 25 Mar 2007
Posts: 1095

PostPosted: Sat Aug 16, 2008 10:18 am    Post subject: Reply with quote

I think what he wants to accomplish is debugging the game without XTrap, so no need to worry about the checks.

@Slugsnack:
lpApplicationName doesn't always give you the application name lol. Sometimes, it's null so you should look at lpCommandLine.
Back to top
View user's profile Send private message
Slugsnack
Grandmaster Cheater Supreme
Reputation: 71

Joined: 24 Jan 2007
Posts: 1857

PostPosted: Sat Aug 16, 2008 11:38 am    Post subject: Reply with quote

I wouldn't know. I only said it was gonna be that cause of your previous post lol. I have only messed around with removing protections a few times before and that was in GunBound in which it was a simple case of unpacking armadillo and stripping it with a similar method outlined in this thread. Anyway if you're looking in Olly after breakpointing at the first instruction of a call you can look at the stack and see all the parameters very easily.
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    Cheat Engine Forum Index -> General programming All times are GMT - 6 Hours
Goto page Previous  1, 2
Page 2 of 2

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001, 2005 phpBB Group

CE Wiki   IRC (#CEF)   Twitter
Third party websites